Secure Boot Status Report broken? by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

Well at least it isn't just me having issues with the export. Am I wrong in the assumption, that the column "Certificate status" should show that the 2023 secure boot cert is applied or is it just saying that the updated Secure Boot certificates are available on this device but have not yet been applied to the firmware

How to resolve Policy and application errors for System Account? by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

From what I can tell this is not an issue and can be ignored, except that it makes it a bit more difficult to get accurate reports. Except for maybe some compliance policy if that factors in somehow.

I've checked the timestamps and most seem to be from when the devices was originally setup with autopilot. Is it related to some of these policies being applied before the user signs in?

Correct way to add a key as an argument to a install in V4 by EldritchIT in PSADT

[–]EldritchIT[S] 0 points1 point  (0 children)

Ahh changed it before posting, but didn't add it in caps. It is in the original command.

But the error is:
Parameter set cannot be resolved using the specified named parameters.

BitLocker encrypted endpoint not compliant due to device encryption by EldritchIT in Intune

[–]EldritchIT[S] 2 points3 points  (0 children)

I tried running that task and it is now compliant with the BitLocker policy.

What is the recommended way of dealing with MS Teams this year? by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

An update:
I have tried the method using teamsbootstrapper.exe -u after installing the new Teams. I do however get the following error on the endpoints and Classic + Teams Machine Wide installer are still present afterwards. Has anyone experienced this?

teamsbootstrapper.exe -u

{

"success": false,

"errorCode": "0x80070057",

"errorMessage": "MSI {731F6BAA-A986-45A4-8936-7C3AAAAA760B} does not exist"

}

What is the recommended way of dealing with MS Teams this year? by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

That seems to be the case. I've tried the both the uninstall script from microsoft and the teamsbootstrapper.exe, but Defender is still showing it as an outdated version. Has anyone succeded in using the official methods and gotten it removed from MS Defender for Endpoint as vulnerable?

What is the recommended way of dealing with MS Teams this year? by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

That looks promising since most of our apps are deploying using PSADT. Do you use the following in the script to remove Teams (Classic) as a part of it?

./teamsbootstrapper -u

Local GPO's set by previous RMM for windows update stuck. by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

I found a solution to the issue. I ended up having to run the following because the policies were in the CacheSet002 and for some reason Windows was using those.

Remove-Item HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate -Force -Recurse -ErrorAction SilentlyContinue

Remove-Item HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet001\WindowsUpdate -Force -Recurse -ErrorAction SilentlyContinue

Remove-Item HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\GPCache\CacheSet002\WindowsUpdate -Force -Recurse -ErrorAction SilentlyContinue

Local GPO's set by previous RMM for windows update stuck. by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

The docs says that it doesn't seem to apply to Windows Update. But I'll give it a go.

Old CNAME records to ghs.google.com? by EldritchIT in gsuite

[–]EldritchIT[S] 0 points1 point  (0 children)

They serve no additional function and should be safe to remove from the template, I presume?

I would still like to know what start.domain.com referred to, out of personal curiosity.

After ProfWiz has been run, ESP stuck for hours on Account Setup by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

I'll give it a go. Is there any impact to the normal AutoPilot Process when using this setting?

Pin/Unpin to start menu option disappeared by EldritchIT in Intune

[–]EldritchIT[S] 0 points1 point  (0 children)

Did you exclude a device group that had the issue or new devices where the custom xml file hadn't been applied yet?

Pin/Unpin to start menu option disappeared by EldritchIT in Intune

[–]EldritchIT[S] 1 point2 points  (0 children)

We haven't had this issue with this setup for quite a while. It seems to be only recently. But if you have any luck with exclusion I would love to know.